deco-performance-audit

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill demonstrates a surface for indirect prompt injection. Ingestion points: Application logs are ingested into the agent context via the SEARCH_LOGS and GET_LOG_DETAILS tools as described in SKILL.md and tools-reference.md. Boundary markers: There are no explicit delimiters or specific instructions for the agent to disregard potential commands contained within the log data. Capability inventory: The skill includes tools for overall performance metrics, top path analysis, and detailed error logging. Sanitization: No validation or sanitization of the log body field is specified before processing.
  • [DATA_EXFILTRATION]: According to the tool definitions in tools-reference.md, the GET_LOG_DETAILS tool provides access to a userEmail field. This allows the processing of Personally Identifiable Information (PII) during the performance audit workflow, which constitutes a data exposure risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 11:22 PM